Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

This rule detects unauthorized or anomalous file modifications or creations to machine learning training datasets (e.g., fine-tuning data, training corpora) by users not belonging to the authorized data engineering group, occurring within one hour of a scheduled training or fine-tuning job execution. This behavioral pattern is indicative of potential data poisoning, where an adversary attempts to inject malicious data into the training set to bias or compromise the resulting model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous data mutations in machine learning training pipelines, such as bulk insertions or label distribution shifts, performed by low-reputation or untrusted contributors. This activity is indicative of attempts to poison model training data to induce backdoors or skew decision boundaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential training data poisoning attempts by monitoring anomalies in ingestion volume, shifts in label distribution, and high-volume submissions from feedback channels. This rule uses statistical analysis to identify spikes in data input or abnormal distributions that deviate from established historical baselines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000